Description
The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's `map_meta_cap` resolves to the `read` primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only `user_pass`, `user_activation_key`, and `session_tokens`, leaving the `wp_capabilities` and `wp_user_level` meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a `wp_update_user_meta` call over the MCP JSON-RPC endpoint with `key=wp_capabilities` and an arbitrary role array such as `{'administrator': true}` targeting their own user ID, causing WordPress to load that account as an Administrator on the next request.
Published: 2026-10-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation to Administrator
Action: Immediate Patch
AI Analysis

Impact

A flaw in the ByteCoreStack – MCP Connector for AI Tools plugin allows an authenticated user with a Subscriber role or higher to overwrite WordPress user capabilities on their own account. The vulnerability lies in the MCP tool that uses WordPress’s wp_update_user_meta function but only checks for the ability to edit a user, which resolves to a read capability when the target ID matches the caller’s ID. Because the meta key blocklist in this plugin does not protect the wp_capabilities and wp_user_level keys, an attacker can set the wp_capabilities meta key to include an administrator role. On the next request, WordPress loads the user as an administrator, granting full site control. The weakness is a classic example of Privilege Escalation (CWE‑269).

Affected Systems

All versions of the ByteCoreStack – MCP Connector for AI Tools plugin for WordPress up to and including 1.2.3 are affected. No specific operating system or WordPress core version is mentioned, but the vulnerability exists in the plugin code itself and therefore applies to any WordPress installation using these plugin versions.

Risk and Exploitability

The flaw carries a high CVSS score of 8.8, indicating significant severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the existence of a user‑authenticating endpoint means that exploitation can occur remotely over the MCP JSON‑RPC interface. Because the attacker only needs to be logged in with a Subscriber‑level account or higher, the risk of exploitation is high in environments where such accounts exist without strict role management.

Generated by OpenCVE AI on October 1, 2026 at 10:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest available version of the ByteCoreStack – MCP Connector for AI Tools plugin.
  • If an immediate upgrade is not possible, modify the plugin code to block write access to the wp_capabilities and wp_user_level meta keys for non‑administrator users, or otherwise unset these keys after any write operation.
  • Ensure that only trusted users have Subscriber or higher roles and audit current role assignments; remove or downgrade any unnecessary high‑privilege accounts.
  • Disable or restrict access to the MCP JSON‑RPC endpoint if it is not required for normal operation.

Generated by OpenCVE AI on October 1, 2026 at 10:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Bytecorestack
Bytecorestack bytecorestack – Mcp Connector For Ai Tools
Wordpress-extensions
Wordpress-extensions bytecorestack
Vendors & Products Bytecorestack
Bytecorestack bytecorestack – Mcp Connector For Ai Tools
Wordpress-extensions
Wordpress-extensions bytecorestack

Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The ByteCoreStack – MCP Connector for AI Tools plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.3 This is due to the `wp_update_user_meta` MCP tool in `execute_tool` gating writes solely with `current_user_can('edit_user', $uid)` — a check that WordPress core's `map_meta_cap` resolves to the `read` primitive when the target user ID matches the caller's own — while enforcing an incomplete meta key blocklist that covers only `user_pass`, `user_activation_key`, and `session_tokens`, leaving the `wp_capabilities` and `wp_user_level` meta keys entirely unprotected. This makes it possible for authenticated attackers with Subscriber-level access and above to elevate their privileges to Administrator by issuing a `wp_update_user_meta` call over the MCP JSON-RPC endpoint with `key=wp_capabilities` and an arbitrary role array such as `{'administrator': true}` targeting their own user ID, causing WordPress to load that account as an Administrator on the next request.
Title ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Bytecorestack Bytecorestack – Mcp Connector For Ai Tools
Wordpress-extensions Bytecorestack
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T07:40:24.252Z

Reserved: 2026-08-13T21:31:00.532Z

Link: CVE-2026-19807

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T08:16:51.390

Modified: 2026-10-01T12:40:28.083

Link: CVE-2026-19807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:36:35Z

Weaknesses
  • CWE-269

    Improper Privilege Management